first of all you need to mirror traffic o the PC NIC using some form on SPAN on a LAN switch.
then on wireshark after the capture you can select one frame of the TCP session and you can use the option called follow TCP stream it will open a child window trying to rebuild the TCP session
Hope to help
Giuseppe
Learn, share, save
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.